Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Mit.1024

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:35.062431617Z 160 PC: 143be | UNKNOWN!
2018-12-17T22:50:35.064628113Z 74 PC: 12bb2 | Reallocate memory
2018-12-17T22:50:35.066508455Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:35.068136113Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:35.07042863Z 42 PC: 12bfb | Get date 0x12bfb: mov byte ptr cs:[0xe], 0
0x12c01: cmp cx, 0x7ca
0x12c05: jbe 0x12c37
0x12c07: cmp al, 1
0x12c09: jne 0x12c37
0x12c0b: cmp dl, 0x10
0x12c0e: jne 0x12c37
0x12c10: push cs
0x12c11: pop ds
0x12c12: mov si, 0x21e
0x12c15: mov dl, byte ptr [si]
0x12c17: xor dl, 0xff
0x12c1a: mov ah, 6
0x12c1c: int 0x21
0x12c1e: inc si
0x12c1f: cmp byte ptr [si], 0xc5
0x12c22: jne 0x12c15
0x12c24: mov ax, 0x700
0x12c27: int 0x21
0x12c29: jmp 0x12c37
2018-12-17T22:50:35.073967849Z 75 PC: 12c43 | Execute program
2018-12-17T22:50:35.090366266Z 9 PC: 132e6 | Display string (String= 'Goat file (EXE/k...). Size=00001A90h/0000006800d bytes. ')
2018-12-17T22:50:35.096550985Z 48 PC: 132ef | Get DOS version
2018-12-17T22:50:35.098527929Z 61 PC: 133bc | Open file (Filename = '')
2018-12-17T22:50:35.105955092Z 93 PC: 1335e | File sharing functions
2018-12-17T22:50:35.108380289Z 9 PC: 132e6 | Display string (String= 'Size change=0400h/01024d. ')
2018-12-17T22:50:35.113463057Z 76 PC: 13343 | Terminate with return code (Return code = '1')
2018-12-17T22:50:35.116843117Z 73 PC: 12c49 | Release memory
2018-12-17T22:50:35.1185795Z 77 PC: 12c4d | Get program return code
2018-12-17T22:50:35.121213017Z 49 PC: 12c5b | Terminate and stay resident (Return code = '1' | Memory size = '112')